<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Secure IM in Gaim with OTR</title>
	<atom:link href="http://www.markshuttleworth.com/archives/89/feed" rel="self" type="application/rss+xml" />
	<link>http://www.markshuttleworth.com/archives/89</link>
	<description>Planetary perspectives</description>
	<pubDate>Sat, 05 Jul 2008 00:19:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Fabian Rodriguez</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-219982</link>
		<dc:creator>Fabian Rodriguez</dc:creator>
		<pubDate>Wed, 19 Dec 2007 00:45:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-219982</guid>
		<description>Just a quick note to let anyone interested know that pidgin (formerly known as gaim) and pidgin-otr will be in the main repository starting with Ubuntu 8.04. ;)</description>
		<content:encoded><![CDATA[<p>Just a quick note to let anyone interested know that pidgin (formerly known as gaim) and pidgin-otr will be in the main repository starting with Ubuntu 8.04. <img src='http://www.markshuttleworth.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu Tomlinson</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-88409</link>
		<dc:creator>Stu Tomlinson</dc:creator>
		<pubDate>Mon, 07 May 2007 15:06:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-88409</guid>
		<description>Paul,

&#62; When folding two users into one, gaim has no way of selecting which of the multiple identities you will use to talk

Pidgin (and Gaim) has a 'Send To' menu to select which identity will be used.

Stu.</description>
		<content:encoded><![CDATA[<p>Paul,</p>
<p>&gt; When folding two users into one, gaim has no way of selecting which of the multiple identities you will use to talk</p>
<p>Pidgin (and Gaim) has a &#8216;Send To&#8217; menu to select which identity will be used.</p>
<p>Stu.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Wouters</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-69336</link>
		<dc:creator>Paul Wouters</dc:creator>
		<pubDate>Tue, 03 Apr 2007 15:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-69336</guid>
		<description>I just noticed this post, and as one of the develors and active promotors of OTR, I'm happy to see the adoption by Mark and others of Ubuntu.

Some ocmments:

- The "double" buttons is really a design problem in gaim. When folding two users into one, gaim has no way of selecting which of the multiple identities you will use to talk. And both might be using the other identity, resulting in two OTR sessions, and thus two buttons.

- "RSA is safer". OTR is designed by two Computer Science professors, both graduates from Berkeley. It's not some "home grown crypto". OTR has other properties that it deems important that public key crypto systems do not have, such as repudiation (you can deny you said something, and the other party will not have any mathematical proof you said it)

- gaim-encryption : from the FAQ: The gaim-encryption plugin provides encryption and authentication, but not deniability or perfect forward secrecy. If an attacker or a virus gets access to your machine, all of your past [monitored] gaim-encryption conversations are retroactively compromised. Further, since all of the messages are digitally signed, there is difficult-to-deny proof that you said what you did: not what we want for a supposedly private conversation!

- cannot use RSA+OTR: it should work. If not, this might be a problem with the RSA plugin. Contact me if you want to see if we can find this issue.

Paul Wouters</description>
		<content:encoded><![CDATA[<p>I just noticed this post, and as one of the develors and active promotors of OTR, I&#8217;m happy to see the adoption by Mark and others of Ubuntu.</p>
<p>Some ocmments:</p>
<p>- The &#8220;double&#8221; buttons is really a design problem in gaim. When folding two users into one, gaim has no way of selecting which of the multiple identities you will use to talk. And both might be using the other identity, resulting in two OTR sessions, and thus two buttons.</p>
<p>- &#8220;RSA is safer&#8221;. OTR is designed by two Computer Science professors, both graduates from Berkeley. It&#8217;s not some &#8220;home grown crypto&#8221;. OTR has other properties that it deems important that public key crypto systems do not have, such as repudiation (you can deny you said something, and the other party will not have any mathematical proof you said it)</p>
<p>- gaim-encryption : from the FAQ: The gaim-encryption plugin provides encryption and authentication, but not deniability or perfect forward secrecy. If an attacker or a virus gets access to your machine, all of your past [monitored] gaim-encryption conversations are retroactively compromised. Further, since all of the messages are digitally signed, there is difficult-to-deny proof that you said what you did: not what we want for a supposedly private conversation!</p>
<p>- cannot use RSA+OTR: it should work. If not, this might be a problem with the RSA plugin. Contact me if you want to see if we can find this issue.</p>
<p>Paul Wouters</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chris penn</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-49035</link>
		<dc:creator>chris penn</dc:creator>
		<pubDate>Thu, 22 Feb 2007 08:38:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-49035</guid>
		<description>I think RSA gaim encryption is more secure.  
Just a note: if it has not been said, you can not use RSA an OTR together.  Although, it looks kinda neat.</description>
		<content:encoded><![CDATA[<p>I think RSA gaim encryption is more secure.<br />
Just a note: if it has not been said, you can not use RSA an OTR together.  Although, it looks kinda neat.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The UbuCon NYC at ISIS Blogs</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-38953</link>
		<dc:creator>The UbuCon NYC at ISIS Blogs</dc:creator>
		<pubDate>Fri, 02 Feb 2007 17:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-38953</guid>
		<description>[...] The UbuCon is an unconference for Ubuntu users, developers, and sysadmins taking place on February 16th at the new Google offices in Manhattan. A few people from ISIS will be there to represent the interest of security in Ubuntu&#8217;s future development and hopefully moving improvements like GCC proactive security measures, encrypted LUKS partitions, and main inclusions of Seahorse and gaim-otr up to a higher development priority. If you&#8217;d like to join us add your name to the RSVP list and we&#8217;ll see you there (it&#8217;s free!).   Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages. [...]</description>
		<content:encoded><![CDATA[<p>[...] The UbuCon is an unconference for Ubuntu users, developers, and sysadmins taking place on February 16th at the new Google offices in Manhattan. A few people from ISIS will be there to represent the interest of security in Ubuntu&#8217;s future development and hopefully moving improvements like GCC proactive security measures, encrypted LUKS partitions, and main inclusions of Seahorse and gaim-otr up to a higher development priority. If you&#8217;d like to join us add your name to the RSVP list and we&#8217;ll see you there (it&#8217;s free!).   Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaby</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-37387</link>
		<dc:creator>Gaby</dc:creator>
		<pubDate>Tue, 30 Jan 2007 18:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-37387</guid>
		<description>zfone inclusion (either native as is in Ekiga CVS or as a proxy or plugin to a to-be-coming gaim-vv work-alike) is quite like this and just as worthy a cause.</description>
		<content:encoded><![CDATA[<p>zfone inclusion (either native as is in Ekiga CVS or as a proxy or plugin to a to-be-coming gaim-vv work-alike) is quite like this and just as worthy a cause.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: required</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-35871</link>
		<dc:creator>required</dc:creator>
		<pubDate>Fri, 26 Jan 2007 22:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-35871</guid>
		<description>Someone should make a cross-platform plug-in for Firefox.</description>
		<content:encoded><![CDATA[<p>Someone should make a cross-platform plug-in for Firefox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SixDays</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-35041</link>
		<dc:creator>SixDays</dc:creator>
		<pubDate>Wed, 24 Jan 2007 23:40:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-35041</guid>
		<description>What is really needed is a plugin to rule them all, on all platforms and for all clients.
According to Sean Egan (lead developer of gaim) the plugin "voice and video" will be incorporated directly into gaim, but he could not give me a timeline for that actually happening.
This may seem of the topic, but it's not.

Many weindogs/winblows/wintendo users on my IM refuses to switch to gaim or even to run it in parallell with the MSN original client solely based on "I need to see webcams".

So I've concluded that either there need to be a cryptoplugin to rule THEM (msn, mirande, amsn, gaim, trillian, icq etc) all or gaim needs to have full webcam support.</description>
		<content:encoded><![CDATA[<p>What is really needed is a plugin to rule them all, on all platforms and for all clients.<br />
According to Sean Egan (lead developer of gaim) the plugin &#8220;voice and video&#8221; will be incorporated directly into gaim, but he could not give me a timeline for that actually happening.<br />
This may seem of the topic, but it&#8217;s not.</p>
<p>Many weindogs/winblows/wintendo users on my IM refuses to switch to gaim or even to run it in parallell with the MSN original client solely based on &#8220;I need to see webcams&#8221;.</p>
<p>So I&#8217;ve concluded that either there need to be a cryptoplugin to rule THEM (msn, mirande, amsn, gaim, trillian, icq etc) all or gaim needs to have full webcam support.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roshan Shariff</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-34939</link>
		<dc:creator>Roshan Shariff</dc:creator>
		<pubDate>Wed, 24 Jan 2007 18:12:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-34939</guid>
		<description>Using Gaim voice chat to exchange shared keys is insecure, since anybody who can intercept your text messages can also listen in on voice conversations. You need to use an out-of-band medium, like the telephone or face-to-face (imagine that!)

&lt;strong&gt;Mark Shuttleworth says:&lt;/strong&gt;

If you know the voice of the person, then you could do the voice confirmation in the same band, as long as you think that it's unlikely that someone could pull off a real-time man in the middle voice substitution attack!</description>
		<content:encoded><![CDATA[<p>Using Gaim voice chat to exchange shared keys is insecure, since anybody who can intercept your text messages can also listen in on voice conversations. You need to use an out-of-band medium, like the telephone or face-to-face (imagine that!)</p>
<p><strong>Mark Shuttleworth says:</strong></p>
<p>If you know the voice of the person, then you could do the voice confirmation in the same band, as long as you think that it&#8217;s unlikely that someone could pull off a real-time man in the middle voice substitution attack!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stephen o'grady</title>
		<link>http://www.markshuttleworth.com/archives/89#comment-34932</link>
		<dc:creator>stephen o'grady</dc:creator>
		<pubDate>Wed, 24 Jan 2007 17:47:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.markshuttleworth.com/archives/89#comment-34932</guid>
		<description>if you're just discovering that, maybe you haven't run across guifications yet. highly recommended if not. 

apt-get install gaim-guifications

then ensure the plugin's activated.</description>
		<content:encoded><![CDATA[<p>if you&#8217;re just discovering that, maybe you haven&#8217;t run across guifications yet. highly recommended if not. </p>
<p>apt-get install gaim-guifications</p>
<p>then ensure the plugin&#8217;s activated.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
